Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

61–70 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#61

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

Browsers should be the things handling cookies, not websites.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#62
post #16

Earlier quoted context omitted.

> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy w…

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

This is definitely not the case.

https://eur-lex.europa.eu/eli/reg/2016/679/oj

You are required to OBTAIN CONSENT from people you want to process the personal data of. Their consent must be INFORMED by telling them who you are and what you intend to do with their data. Their consent must be FREELY GIVEN and can be WITHDRAWN at any time.

That's what's at stake; not the cookies/state themselves, but how you intend to process the data of individuals. As long as you are not profiling natural individuals, no matter how they leave traces, then you don't need to ask for their consent.

It's bad-faith people, who clearly want to process personal data, who make a huge fuss and tell you everyone needs a cookie banner. Mainly because they are raging that they can't data-mine and monetise every last byte of data they can get, without the consent of the individuals they're profiting from.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#63

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

>> a) do away with the worthless cookie banners requirement

My understanding is that if your site doesn't use cookies, you don't even need that. Don't use cookies, don't collect or share personal data, and GDPR is complied with. Apparently from TFA it sounds like even then you have a lot of proving it to the government, and that's a hassle.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#64
post #16

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy w…

[deleted]

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#65
post #21
post #5

The politicians cite competitiveness as the motivator for relaxing the GDPR. The real reason for the EU lagging behind the US in "big tech" is of course the lack of venture capital and the red tape in registering corporations. The GDPR does not prevent US big tech from operating in the EU. As it stands, this is just another attack on EU citizens' rights. It is also the least of the EU's current problems. De-industria…

> The GDPR does not prevent US big tech from operating in the EU. Of course it doesn't, that'd be stupid. But it does require them to be compliant, otherwise they'll face fines and eventually they'll chose to either be compliant, or exit the market. As a EU citizen with rights, I love this, exactly what I want from my inter-continent union of countries.

> otherwise they'll face fines and eventually they'll chose to either be compliant, or exit the market.

Or declare war against the EU, which is the option they've gone for.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#66
post #57
post #35

Earlier quoted context omitted.

I don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.

The cookie banners don't make companies less "careless" They just introduce a needless bit of friction in the UX. If the EU wanted to prevent digital identity triangulation or cross-domain advertising data gathering, it should have banned it outright. Rather than getting all users to click a stupid banner every time they visit a website.

So, since they didn't ban it outright, doesn't it make it clear that the goal wasn't to remove it fully? The goal was to let users be informed about it, so they can make their own choice, not to remove the choice at all.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#67
post #60
post #27

Earlier quoted context omitted.

> You are required to have a cookie banner if you use cookies Feel free to (re)read the regulation, there is no such requirement at all. > you must serve a cookie banner even if you are only using functional cookies Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.

No. The reason it exists is businesses get guidance from legislators and existing case law on what prevents you from running a foul of GDPR and the cookie banner is what we ended up with. If those banners did nothing, companies wouldn't include them. They are there as the lowest effort legal defense.

Again, the cookie banners have nothing to do with GDPR, where are people getting this misinformation from?! Was there a popular article saying we have those cookie banners because of GDPR, or what?

The banners are the result of much earlier directives that predate GDPR by a lot...

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#68
post #19

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

I believe uBlock Origin can automatically do this by enabling "EasyList – Cookie Notices" in the extension settings. If you have this extension installed, there's no need to install another.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#69
post #54

I think the title is clickbait'y. The EU proposes to simplify the law rather than abolish it, which makes sense to me.

And in the world of bureaucracy, "simplification" doesn't mean what you'd think it should mean. "Simplification" consists in adding exceptions, which are in effect additional rules and special cases. Simplification actually means everything gets more complex.

We live in an Orwellian world:

  War is peace.
  Freedom is slavery.
  Ignorance is strength.
  Simplification is complication.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#70
post #2

Uh oh. I'm all for cutting the red tape, but (in my opinion) the GDPR is: 1) easy to comply with if you're not doing nasty stuff with people's data, 2) actually needed. Any opposing views?

I shut down a couple of my websites that provided a service for free (streetlend.com and cointouch.com) because the GDPR was too ambiguous for me to be 100% sure I complied with - and in the past online I have encountered vexatious people who have to tried to damage my reputation. On one of my other websites, those people used GDPR privileges (eg making vexatious SAR requests) simply to make my life more difficult.

At the end of the day, I create helpful and fun websites for free in my spare time because I enjoy it.

EU regulation created jeopardy and friction that meant I couldn't justify doing this anymore.

Post reply on HN